The latest addition to Defender for Containers, Agentless Discovery for Kubernetes, empowers security-conscious organizations with new capabilities to gain insights into the security landscape of their Kubernetes workloads.
Previously available for customers in Defender Cloud Security Posture Management (DCSPM), it is now being integrated as a core component of Defender for Containers. Agentless Discovery empowers you to gain higher visibility into the security landscape of your Kubernetes workloads, if you choose not to install additional agents.
In Defender for Containers, the following capabilities are made possible by enabling Agentless Discovery for Kubernetes:
As a complement to the introduction of Agentless Discovery, it's important to consider its benefits in relation to the existing agent-based approach. If you're looking for a comprehensive understanding of these two options, Microsoft has provided a detailed comparison in a previous blog post titled "Comprehensive Guide on Agent-Based and Agentless Cloud Security".
In the comparison guide, you'll explore:
Capability categories |
Agentless / Agent based |
Vulnerability assessment for running images |
Can utilize either Defender profile (agent based) or Agentless discovery for Kubernetes (or both) |
Run-time threat protection |
Needs both Defender profile (agent based) and Audit-log (agentless) for full value |
Context-graph based capabilities (Security Explorer, K8S inventory, K8S insights, risk hunting, visualization of VA across K8S workloads) |
|
Defender for Containers customer who don’t have the “Agentless discovery for Kubernetes” extension enabled as part of Defender CSPM, are encouraged to manually enable the extension in the “Environments and settings” blade of Defender for Containers.
We encourage you to update your subscriptions to have the full set of extensions enabled, and thus benefit from the latest additions and features.
Note: enabling the latest additions will not incur new costs to active Defender for Containers customers.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.